First published: Mon Mar 11 2013(Updated: )
The Emerson DeltaV SE3006 through 11.3.1, DeltaV VE3005 through 10.3.1 and 11.x through 11.3.1, and DeltaV VE3006 through 10.3.1 and 11.x through 11.3.1 allow remote attackers to cause a denial of service (device restart) via a crafted packet on (1) TCP port 23, (2) UDP port 161, or (3) TCP port 513.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson DeltaV SE3006 SD Plus Controller | <=11.3.1 | |
Emerson DeltaV VE3005 Controller MD | <=10.3.1 | |
Emerson DeltaV VE3005 Controller MD | <=11.3.1 | |
Emerson DeltaV VE3006 Controller MD Plus | <=10.3.1 | |
Emerson DeltaV VE3006 Controller MD Plus | <=11.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4703 has a medium severity rating due to its potential to cause a denial of service.
To fix CVE-2012-4703, apply the latest security patches provided by Emerson for the affected DeltaV products.
CVE-2012-4703 affects Emerson DeltaV SE3006, VE3005, and VE3006 controllers with specific versions up to 11.3.1 and 10.3.1.
CVE-2012-4703 can be exploited by remote attackers sending crafted packets via TCP port 23, UDP port 161, or TCP port 513.
Exploitation of CVE-2012-4703 can lead to unexpected device restarts, impacting system availability and reliability.